Privacy Policy

Last updated: July 23, 2026

1. Information We Collect

ApexFlow AI collects information that allows us to provide AI communication and automation services to businesses. The types of information we may collect include:

  • Contact form information: Name, business name, email address, phone number, business type, preferred contact method, and best time to contact you, submitted through our website contact form.
  • Call and text data: When a business uses ApexFlow to handle customer calls or text messages, we process the content of those communications to provide the AI assistant service. This may include the customer's name, phone number, and the details of their request.
  • Appointment information: Client name, contact details, service type, requested date and time, and appointment status.
  • Business information: Services offered, hours, pricing, service areas, policies, and frequently asked questions that a business configures for its AI assistant.
  • Account information: Email address and role (admin or user) for authenticated users of the ApexFlow platform.

2. How We Use Your Information

We use the information we collect to:

  • Provide AI receptionist, messaging, and appointment booking services
  • Respond to contact form submissions and set up trials or paid plans
  • Send appointment confirmations, reminders, and follow-up messages on behalf of businesses
  • Operate, maintain, and improve the ApexFlow platform
  • Communicate with businesses about their account, billing, and service updates

3. Cookies and Analytics

ApexFlow may use cookies and similar technologies to operate the website and understand how visitors use it. We may use analytics tools to collect aggregate, non-personal information about website usage. You can control cookies through your browser settings.

4. Third-Party Providers

ApexFlow works with third-party service providers to deliver its services, which may include:

  • Telephony and SMS providers (for call and text messaging services)
  • AI and language model providers (for conversational AI capabilities)
  • Payment processors (for subscription billing)
  • Cloud hosting and data storage providers

These providers process data only as necessary to deliver the services we have requested. We do not sell or rent your personal information to third parties.

5. Data Storage

Business and customer data is stored on secure cloud infrastructure. Access to data is restricted through authentication, role-based authorization, and row-level security controls. Sensitive credentials such as API keys and tokens are stored in secure server-side environment variables and are never exposed in frontend code, page source, or public database records.

6. Data Deletion Requests

You may request deletion of your personal information at any time. Businesses may request deletion of their customer data, conversation history, and business settings. To submit a data deletion request, contact us at sterlingtvickers@gmail.com or 949-531-8755. We will process your request within a reasonable timeframe.

7. Business Customer Responsibilities

Businesses using ApexFlow are responsible for:

  • Obtaining proper consent from their customers before sending automated text messages or recording calls, where applicable
  • Providing accurate business information for the AI assistant to use
  • Maintaining the accuracy of their services, hours, pricing, and policies
  • Responding to their customers' opt-out requests (e.g., replying STOP to text messages)
  • Ensuring their use of ApexFlow complies with applicable laws and regulations

8. SMS and Call Consent

When a business uses ApexFlow for SMS messaging, customers may opt out of text messages at any time by replying STOP to any message. For help, customers may reply HELP. Standard message and data rates may apply. ApexFlow does not send automated marketing texts without proper consent from the recipient.

The AI assistant always identifies itself as an AI assistant for the business and never pretends to be a human employee.

9. Data Security

We take reasonable measures to protect your data, including encrypted connections, role-based access controls, row-level security on all sensitive data, and secure storage of API credentials. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

ApexFlow has not completed HIPAA, SOC 2, PCI, or other formal security certifications. We do not claim compliance with any certification we have not formally completed and verified.

10. Changes to This Policy

We may update this Privacy Policy at any time. Continued use of the service after changes constitutes acceptance of the updated policy. We will note the updated date above.

11. Contact

Questions about this Privacy Policy? Contact us at: